HTC WM6.1 and WM6 Bluetooth Vulnerability


Bluetooth Vulnerability

Bluetooth Vulnerability


HTC devices running Windows Mobile 6 and Windows Mobile 6.1 are prone to a directory traversal vulnerability in the Bluetooth OBEX FTP Service. Exploiting this issue allows a remote authenticated attacker to list arbitrary directories, and write or read arbitrary files, via a ../ in a pathname. HTC handsets running Windows Mobile 5 are not affected. Users worried about the vulnerability should avoid pairing their phones with an untrusted handset or computer. They may also want to delete any devices that are already paired with their phones. Because the driver, obexfile.dll, is an HTC driver, only handsets from the company are affected. Apparently Windows Mobile 6.5 devices will be vulnerable too if HTC does not fix the driver according to Moreno Tablado, who discovered this Vulnerability.

[ via PC World ]

More info about the Vulnerability

Sponsor

Similar Apps Download


Stumble
Delicious
Technorati
Facebook


Tags:

blog comments powered by Disqus